CVE-2025-67077

File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the UploadTmpFile action.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-15 16:16

Updated : 2026-01-21 14:45


NVD link : CVE-2025-67077

Mitre link : CVE-2025-67077

CVE.ORG link : CVE-2025-67077


JSON object : View

Products Affected

agora-project

  • agora-project
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type